Skip to content
CommVault SystemsCVE-2026-77106

Commvault Cloud: missing authorization

High7.7CVE-2026-77106 · Published Sep 8, 2026 · updated Sep 11, 2026

Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

CommVault Systems advisory

Affected versions

PackageAffectedFixed in
Commvault Cloud
Product
>= 11.46.0, <= 11.46.19No fix yet
>= 11.44.0, <= 11.44.19No fix yet
>= 11.40.0, <= 11.40.71No fix yet
>= 11.36.0, <= 11.36.122No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-862

More CommVault Systems advisories

All CommVault Systems
Advisory
Commvault Cloud: authentication bypass
High8.7Sep 8
Commvault Cloud: path traversal
High8.3Sep 8
Commvault Cloud: improper signature check
High8.7Sep 8
Commvault Cloud: authentication bypass
Critical9.3Sep 8
Commvault Cloud: path traversal
High8.5Sep 8
Commvault Cloud: unsafe deserialization
High7.3Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.